Data Protection & Technical Security

Last updated: 1 September 2026

Data Controller (GDPR Art. 13):

Umair Javaid, trading as “HalalKnot”

CRO business-name registration is pending.

Legal form: Individual sole trader established in Ireland. HalalKnot is not an incorporated or limited company.

Correspondence address: Ireland — postal address available on request (email below is the primary contact)

Email: connect.hk@outlook.com

Umair Javaid, trading as HalalKnot, is the controller of the personal data you provide. The Service is established in Ireland and processes data in accordance with the GDPR and the Irish Data Protection Act 2018.

1. Data Architecture & Infrastructure

HalalKnot uses hosted infrastructure supplied by Vercel and Supabase. These services provide controls that support availability and separation of application data, but no online service can eliminate all risk.

  • Frontend & Edge: Hosted on Vercel. Supported browser connections use HTTPS/TLS while data is transmitted.
  • Backend & Database: Powered by Supabase (PostgreSQL). Our configured project region is AWS EU-West-1 (Ireland). Regional hosting supports our data-protection approach but does not, by itself, establish GDPR compliance.

2. Technical Security Measures

A. Data Encryption

  • In-Transit:Supported connections between the user's browser and our hosted services use HTTPS/TLS.
  • At-Rest: Supabase documents encryption controls for stored database data and backups. The precise controls are managed by the provider and may change.

B. Access Control — Row-Level Security

  • Row-Level Security (RLS):We use PostgreSQL RLS policies to restrict access to private records. Contact disclosure is handled through authorised server endpoints after a mutual connection and according to the member's sharing choice.
  • Authentication: Supabase-issued session tokens are used to authenticate requests. Logout and session-expiry controls limit continued access.

C. Frontend Security (Vercel)

  • Environment Variables: All API keys and secrets (like the Supabase Service Role Key) are configured as server-side environment variables and are not intentionally included in client-side application bundles.
  • CSP Headers: We implement Content Security Policy (CSP) headers as one control intended to reduce Cross-Site Scripting (XSS) and injection risk.

3. Special Category Data

HalalKnot does not collect explicit religion or sect fields — no such input fields exist in the system. However, because HalalKnot is a Muslim matrimonial service, your membership and the values-related information you provide may indicate your religious beliefs, which is special-category data under GDPR Article 9. We process it only on the basis of the explicit consent you provide at sign-up, and you may withdraw that consent at any time by deleting your account.

Profile photos are processed for content moderation purposes only (see §4 below). Photos are not used for facial recognition or biometric identification, and are not retained by our moderation provider beyond the automated screening request.

4. Data Processing Agreements (DPA)

We maintain active DPAs with our primary sub-processors to ensure they adhere to EU privacy standards:

  • Supabase, Inc: Handles database storage, authentication, and file storage. Data stored in AWS EU-West-1 (Ireland).
  • Vercel, Inc: Handles frontend hosting, edge functions, and analytics.
  • Sightengine: Automated content moderation of profile photos. Photos are submitted for screening on upload; results are returned and photos are not stored by Sightengine beyond the request.
  • Resend: Transactional email delivery (connection notifications, account emails). Governed by SCCs for data transferred outside the EU.

5. Data Retention & Deletion Procedure

  • User-Initiated Deletion: When a user clicks "Delete Account," a "Hard Delete" is triggered. Supabase RLS and Foreign Key constraints ensure all associated active private contact information and profile content are removed from the live service. A random profile identifier and deletion timestamp remain as a non-reusable tombstone for shared links.
  • Backup Retention: Database backups are kept for 30 days for disaster recovery, after which they are permanently overwritten.
  • Safety and anti-abuse records: A one-way email hash is retained for 30 days after voluntary deletion. Reports, moderation records and longer restrictions associated with banned accounts may be kept where necessary to investigate abuse, protect members, establish legal claims or prevent ban evasion. Access is restricted to authorised administrators.

6. Breach Notification Procedure

In the event of a suspected data breach:

  • Identification: Our team will be alerted via Supabase/Vercel monitoring logs.
  • Assessment: Within 24 hours, we will determine the scope of the impact.
  • Notification: If the breach poses a risk to users, we will notify the Irish Data Protection Commission (DPC) and affected users within 72 hours, as required by GDPR Articles 33 and 34.

For questions about data protection or to exercise your rights, please contact us at connect.hk@outlook.com